Industry update· 4 Sept 2026
The April 2026 Cyber Essentials update, and why it catches even already-certified businesses out
Cyber Essentials moved to v3.3, the "Danzell" update, in April 2026. If you certified a year or two ago and haven't looked at it since, that matters more than it sounds: the standard doesn't stand still, and a pass under an older question set isn't a guarantee you'd pass under this one.
The five control areas haven't changed: firewalls, secure configuration, patch management, access control, and malware protection. What's changed is how strictly the current rules apply to situations most businesses assumed were out of scope.
Two examples come up constantly. First, multi-factor authentication now clearly applies to free and personal-tier tools holding company data, a Trello board, a free Slack workspace, a personal Dropbox someone started using for work, not just the systems IT formally signed off. Second, the 14-day critical patch rule is an automatic fail, and it's specifically the gap between "we patch monthly" and "critical patches need action within 14 days" that trips businesses who genuinely do patch, just not fast enough for the most severe updates.
The 14-day critical patch rule is an automatic fail, and it's specifically the gap between "we patch monthly" and "critical patches need action within 14 days" that trips businesses who genuinely do patch, just not fast enough.
Neither of these is a new idea. What's changed is that assessors are checking for them more consistently, which means gaps that went unnoticed in a previous assessment are more likely to surface in this one. If you don't find out what's missing before an assessor does, an insurer or an attacker eventually will, on their timeline, not yours.
Worth knowing
If it's been a while since you looked at where you actually stand, run the free 5-minute readiness check against the current rules, or book a free 30-minute call if you'd rather talk it through. For the mechanics of the two rules above in more detail, see the guides on the 14-day patch rule and MFA on free SaaS tools.